Wu-ftpd message Buffer Overflow Vulnerability
BID:726
Info
Wu-ftpd message Buffer Overflow Vulnerability
| Bugtraq ID: | 726 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 19 1999 12:00AM |
| Updated: | Oct 19 1999 12:00AM |
| Credit: | Exposed in AusCERT advisory AA-1999.02, published on October 19, 1999. |
| Vulnerable: |
Washington University wu-ftpd 2.5 .0 |
| Not Vulnerable: |
Washington University wu-ftpd 2.6 .0 |
Discussion
Wu-ftpd message Buffer Overflow Vulnerability
There is a buffer overflow in wu-ftpd message file expansions which may be remotely exploitable. In situations where the message file can be written to in some way remotely by regular or anonymous users, this may result in a root compromise. This detailed in an AUSCERT advisory AA-1999.01.
There is a buffer overflow in wu-ftpd message file expansions which may be remotely exploitable. In situations where the message file can be written to in some way remotely by regular or anonymous users, this may result in a root compromise. This detailed in an AUSCERT advisory AA-1999.01.
Exploit / POC
Wu-ftpd message Buffer Overflow Vulnerability
Exploit available:
Exploit available:
Solution / Fix
Wu-ftpd message Buffer Overflow Vulnerability
Solution:
Upgrade to the newest version of wu-ftpd not vulnerable to this problem (2.6.0 as of Oct 20, 1999), available at the location below:
ftp://ftp.wu-ftpd.org/pub/wu-ftpd/
Solution:
Upgrade to the newest version of wu-ftpd not vulnerable to this problem (2.6.0 as of Oct 20, 1999), available at the location below:
ftp://ftp.wu-ftpd.org/pub/wu-ftpd/
References
Wu-ftpd message Buffer Overflow Vulnerability
References:
References: